Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

Penetration Testing for Ottawa Startups

Penetration testing for Ottawa startups means hiring a Canadian-based team to simulate real attacks against your product before a federal buyer, a prime contractor, or an enterprise customer asks for proof it's already been done. In a city where the largest customers in the room are the Government of Canada and the defence primes that supply it, a penetration test isn't a nice-to-have for the security page. It's the document that gets your deal past procurement.

Why Ottawa Founders Get Asked for Penetration Testing More Than Most

Ottawa's startup economy sits on top of two buyers that almost nowhere else in Canada has at this density: the federal government and the defence and intelligence contractors clustered around Kanata North. If you're selling software into that ecosystem, whether directly to a department or as a subcontractor to a prime, you will eventually hit a security questionnaire that asks for a current penetration test report, not a self-assessment. Procurement teams in Ottawa are used to seeing SOC 2 reports and pen test attestations from vendors twice your size, and they apply the same bar to a twelve-person startup as they do to an established integrator.

This is different from the pressure a Toronto fintech feels from a bank, or a Vancouver SaaS company feels from a US enterprise logo. Ottawa's pressure is procurement-driven and often tied to specific frameworks: ITSG-33 controls or PBMM cloud profiles. A generic vulnerability scan report doesn't satisfy any of that. Buyers want evidence of a methodology-driven test, performed by someone who understands what "adequate" looks like in a federal context.

What a Real Penetration Test Covers (and What a Scan Doesn't)

A lot of vendors sell automated vulnerability scanning and call it penetration testing. The two are not the same thing, and Ottawa buyers who've been through federal procurement cycles usually know the difference. A proper penetration test involves a human tester actively trying to exploit weaknesses, chain findings together, and demonstrate real business impact, not just list CVEs a scanner flagged.

  • External network and application testing, covering your public-facing infrastructure and web or API surface
  • Internal testing, simulating what an attacker could do after gaining a foothold inside your environment
  • Cloud configuration review, especially for teams running on Azure Government or AWS GovCloud-adjacent environments common in the Ottawa federal supply chain
  • Authenticated application testing, exercising your product the way a malicious user or compromised account would
  • A written report mapped to how buyers actually evaluate risk, with severity ratings, reproduction steps, and remediation guidance, not just a raw findings dump

traztech's penetration testing is led by Jacob Masse, a published security researcher credited with five CVEs, including CVE-2024-45163, a CVSS 9.1 finding that functioned as a kill-switch against the Mirai botnet. That's the calibre of offensive work behind the assessment, applied directly to your product rather than outsourced to a subcontractor you'll never speak with.

Need the testing done? Penetration testing and vulnerability management, with the retest that proves a finding is actually closed. Penetration testing

The Ottawa Ecosystem: Kanata North, Federal Contracts, and the Trust Bar

Kanata North is one of the densest technology clusters in Canada, built heavily on defence, telecom, and photonics companies that have spent decades working with federal security requirements. If your startup is based there, or anywhere in the National Capital Region, the companies around you are already fluent in security due diligence. That raises the trust bar for everyone else in the ecosystem, including early-stage SaaS companies that have nothing to do with defence but sell into adjacent government departments.

It also means Ottawa founders can't treat security as something to bolt on before a Series A. A federal buyer's procurement office will ask for evidence during the RFP stage, not after the contract is signed. Startups that wait until a deal is blocked to book a pen test lose weeks they don't have in a procurement cycle that's already slow. Building the relationship with a testing partner early, before the report is urgently needed, is what keeps a federal or defence-adjacent deal moving instead of stalling in security review.

Penetration Testing vs. Broader Security Readiness

A penetration test answers one question well: can an attacker break into this system today. It doesn't answer whether your access controls, vendor management, or incident response process would hold up to a SOC 2 audit. Ottawa companies increasingly need both: a pen test to prove technical resilience, and a broader security program to prove operational maturity. Our security services cover the full picture, from the offensive testing work through to the governance and monitoring buyers expect to see documented.

Why a Canadian Boutique Beats a Remote Vendor for This Work

Plenty of penetration testing firms will sell into Ottawa without ever setting foot there, treating the National Capital Region the same as any other market on a sales list. That works fine for a generic SaaS company. It doesn't work well when your buyer wants to know their data stays in Canada, your team understands Canadian frameworks like PIPEDA and the federal PBMM profile without a translation layer, and you can get a straight answer on a call instead of a ticket queue.

traztech is a Canadian boutique consultancy, not a reseller of an offshore testing pipeline. We serve founders across the country's major tech hubs directly, from Ottawa and Toronto to Waterloo, Montreal, Calgary, and Vancouver, with the same senior-led approach regardless of company size. For an Ottawa startup navigating federal procurement, that means working with someone who already understands the buyer on the other side of the table, not someone learning the Canadian public sector landscape on your dime.

Getting Started with a Penetration Test in Ottawa

The right time to start is before a deal depends on it. A well-scoped penetration test typically takes a few weeks from kickoff to final report, and that timeline gets tighter, not longer, the closer you are to a procurement deadline. Startups that treat testing as an ongoing part of their security posture, rather than a one-time box to check, are the ones that clear federal and defence procurement reviews without scrambling.

If you're building toward a federal contract, a defence prime relationship, or simply need to answer a customer's security questionnaire with something more credible than a scan report, get in touch with traztech to scope a penetration test built around what your Ottawa buyers actually expect to see.

What Federal Procurement Actually Asks For, Line by Line

Ottawa founders often describe the requirement vaguely, as "they want security stuff." The requirement is usually more specific than that, and knowing which document is being asked for saves weeks.

If the contract carries a Security Requirements Check List, the security conditions are attached to the contract itself rather than to a general policy, and they will state whether your organization needs screening under the Contract Security Program, whether individuals need Reliability Status or a higher level, and whether protected information will be stored or processed on your systems. That is an organizational clearance question, and a penetration test does not answer it.

Separately, the technical evaluation criteria may ask for evidence of independent security testing within a stated period, commonly twelve months. That is where the penetration test lives. A third strand, the Supply Chain Integrity process, looks at your ownership, your suppliers, and where your product is built and hosted.

These strands are evaluated by different people on different timelines, and they fail independently. A startup with an excellent test report and no organizational screening is just as blocked as one with clearance and no test. Read the solicitation, list which of the four applies, and assign each an owner before you start buying anything.

Where a Pentest Fits Inside ITSG-33 and the PBMM Profile

When a departmental security assessor tells you they follow ITSG-33, they are working from a control catalogue and a security control profile appropriate to the sensitivity of the information involved. The Protected B, Medium Integrity, Medium Availability profile is the one most commonly cited for cloud-hosted services handling protected information.

Within that structure, a penetration test is evidence against a specific set of expectations rather than proof of the whole profile. It speaks to security assessment activity, to developer security testing where you build the software yourself, and to vulnerability identification and remediation. It says nothing about your personnel screening, your media handling, your physical security, or your continuity planning. Assessors know this, which is why a strong test report submitted in place of a control mapping tends to come back with more questions rather than fewer.

The practical move is to submit the test as one exhibit inside a control response, with a short statement of which controls it evidences and which it does not. Assessors respond well to a vendor who draws that line themselves. It reads as competence, and it stops the report being over-read and then challenged.

The Tester Questions Federal and Defence Buyers Actually Ask

Beyond the technical quality of the work, buyers in this market ask a set of questions about the testers that most commercial buyers never raise. Ask your prospective vendor these before you sign, because you will be asked them afterward.

Who performed the test, and are they Canadian-based? Named individuals, resident in Canada, working directly on your environment. If the firm subcontracts to an offshore delivery pipeline, that will surface in a supply chain review, and it will surface at the worst possible moment.

Do any of the testers hold personnel security screening? If the engagement touches protected information or systems inside a cleared environment, the answer matters. If it does not, be honest about that too rather than pretending the requirement exists.

Where does the evidence live? Screenshots, extracted data samples, credentials and the draft report all sit somewhere during the engagement. Buyers ask where. A firm that cannot tell you which country its ticketing system, file storage and note-taking tools run in has not thought about this, and you will inherit the problem.

What happens to the data afterward? Retention period, deletion process, and whether they will confirm deletion in writing. Put a number in the agreement.

Will they stand behind the report? Federal reviewers occasionally come back with questions months later. Ask whether follow-up clarification is included or billable, and whether the tester who did the work will be the one answering.

Timing the Test Against a Procurement Calendar

Procurement timelines are unforgiving in a specific way: the windows are short and they are hard. A solicitation may allow a limited period for bidder questions, then close bid submission on a fixed date. If the requirement for independent testing appears in the technical criteria and you read it two weeks before close, you are not going to complete scoping, testing, remediation and a retest in time. A well-run engagement is a few weeks end to end, and remediation depends on your engineering capacity, not the tester's.

The workable pattern for an Ottawa company with federal ambitions is to decouple the test from any individual bid. Run it annually on a schedule you control, dated so the report is always inside a twelve-month window when a solicitation drops, and treat significant architecture changes as a trigger for an additional targeted test. That way the answer to "do you have a current penetration test" is yes on the day you are asked, rather than a request for an extension.

The second timing trap is the prime contractor relationship. If you subcontract to a defence prime, their obligations flow down to you through the subcontract, and the prime's own vendor security review runs on the prime's schedule. That review often lands after you have already been selected commercially, which creates a stretch where the work is won but not started. Ask the prime early what their vendor onboarding requires, in writing.

What the Report Needs to Contain for This Audience

A report written for a commercial SaaS buyer and one written for a federal or defence-adjacent reviewer differ in a few concrete ways.

The scope statement has to be unambiguous about environments and boundaries, naming the systems tested and explicitly listing what was excluded and why. Reviewers in this market read exclusions carefully.

The methodology should name a recognized public standard rather than describing the firm's proprietary approach, so the reviewer can calibrate depth without taking your word for it.

The tester identity and credentials should be stated. Anonymous vendor reports carry less weight here than almost anywhere else.

The remediation status needs to be current, with a retest letter where findings have been closed. An open critical with a dated plan and a named owner is workable. An open critical with no plan reads as an unmanaged risk, and that is the reading that stalls a file.

Finally, keep a redacted version. You should not be circulating live reproduction steps for unfixed vulnerabilities through a procurement portal. A summary attestation covering scope, dates, methodology, severity counts and closure status is the right artefact for wide distribution, with the full technical report available under a signed agreement to the assessor who needs it.

Budgeting for This at Seed Stage

The honest range in this market is wide, and it is driven by scope rather than by postcode. traztech's penetration testing starts from $1,000, and the reason the floor is that low is that a narrow, precisely scoped test of a single application with two roles is genuinely a smaller piece of work than a full external, internal and cloud review. Most Ottawa startups do not need the second thing in year one.

What tends to blow the budget is buying breadth you cannot act on. A test covering five environments produces findings across five environments, and a six-person engineering team fixes them at the same rate regardless. Scope to what you can remediate inside a quarter, then widen next year. The full fixed-scope pricing is published rather than quoted per call, which makes it easier to plan a year of testing against a procurement calendar instead of reacting to each solicitation.

When a Penetration Test Is Not What You Need

Some situations where booking a test is the wrong purchase, even in this market.

You need a threat and risk assessment instead. Departments frequently ask for a TRA, which is a documented analysis of threats, vulnerabilities and safeguards against the sensitivity of the information involved. That is an analytical deliverable. A penetration test can feed it, but it is not a substitute, and turning up with a test report when a TRA was requested restarts the clock.

The blocker is organizational screening. If you have no Designated Organization Screening and the contract requires it, that process has its own timeline and no amount of security testing accelerates it. Start it early and separately.

You have no federal pipeline yet. If the Ottawa location is the only reason this is on your list, and your customers are commercial companies who have not asked, wait. Test when a buyer's requirement or your own risk position calls for it, not because of the address on your incorporation documents.

Need the testing done? Penetration testing and vulnerability management, with the retest that proves a finding is actually closed.

Penetration testingOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on vulnerability management. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.